Integer Underflow Vulnerability in STMicroelectronics X-CUBE-AZRTOS-WL HTTP Server
CVE-2024-50596
4.3MEDIUM
What is CVE-2024-50596?
An integer underflow vulnerability in the HTTP server implementation of STMicroelectronics X-CUBE-AZRTOS-WL version 2.0.0 poses a risk of denial of service. By sending a specially crafted network packet, an attacker can exploit this vulnerability to disrupt the service. The issue is rooted in the NetX Duo Web Component, particularly in the functionality handling HTTP PUT requests, which can be found in the source code file nx_web_http_server.c. This flaw allows for potential service interruptions, highlighting the need for secure coding practices and timely updates to mitigate such risks.
Affected Version(s)
X-CUBE-AZRT-H7RS 1.0.0
X-CUBE-AZRTOS-F4 1.1.0
X-CUBE-AZRTOS-F7 1.1.0